Branch was auto-updated.

This commit is contained in:
srv-rr-gh-researchbt
2023-04-18 14:56:25 -07:00
committed by GitHub
14 changed files with 1314 additions and 811 deletions
+1 -1
View File
File diff suppressed because one or more lines are too long
+1 -1
View File
File diff suppressed because one or more lines are too long
+1 -1
View File
File diff suppressed because one or more lines are too long
+1 -1
View File
@@ -5,7 +5,7 @@
"id": {
"group": null,
"name": "DA-ESS-ContentUpdate",
"version": "3.64.0"
"version": "4.0.0"
},
"author": [
{
File diff suppressed because one or more lines are too long
+2 -2
View File
@@ -4,7 +4,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 12867
build = 13203
[triggers]
reload.analytic_stories = simple
@@ -20,7 +20,7 @@ reload.es_investigations = simple
[launcher]
author = Splunk
version = 3.64.0
version = 4.0.0
description = Explore the Analytic Stories included with ES Content Updates.
[ui]
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-04-11T20:14:03 UTC
# On Date: 2023-04-18T21:44:55 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -1,2 +1,2 @@
[content-version]
version = 3.64.0
version = 4.0.0
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-04-11T20:14:03 UTC
# On Date: 2023-04-18T21:44:55 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+41 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-04-11T20:14:03 UTC
# On Date: 2023-04-18T21:44:55 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -3669,6 +3669,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_bootloader_inventory_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_cached_domain_credentials_reg_query_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -3821,6 +3825,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_dns_gather_network_info_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_dotnet_binary_in_non_standard_path_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -3861,6 +3869,14 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_exfiltration_over_c2_via_invoke_restmethod_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_exfiltration_over_c2_via_powershell_uploadstring_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_export_certificate_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -3945,6 +3961,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_impair_defenses_disable_hvci_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_impair_defenses_disable_win_defender_auto_logging_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -4305,6 +4325,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_rdp_connection_successful_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_registry_certificate_added_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -4373,6 +4397,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_scheduled_task_created_via_xml_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_scheduled_task_with_highest_privileges_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -4381,6 +4409,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_screen_capture_via_powershell_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
[windows_security_account_manager_stopped_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
@@ -4962,6 +4994,10 @@ description = customer specific splunk configurations(eg- index, source, sourcet
definition = sourcetype=mscs:azure:eventhub
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
[bootloader_inventory]
definition = sourcetype = PwSh:bootloader
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
[brand_abuse_dns]
definition = lookup update=true brandMonitoring_lookup domain as query OUTPUT domain_abuse | search domain_abuse=true
description = This macro limits the output to only domains that are in the brand monitoring lookup file
@@ -5446,6 +5482,10 @@ description = This macro limits the output to files that have extensions associa
definition = lookup ransomware_notes_lookup ransomware_notes as file_name OUTPUT status as "Known Ransomware Notes" | search "Known Ransomware Notes"=True
description = This macro limits the output to files that have been identified as a ransomware note
[remoteconnectionmanager]
definition = source="WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational"
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
[remove_valid_domains]
definition = eval domain=trim(domain,"*") | search NOT[| inputlookup domains] NOT[ |inputlookup cim_corporate_email_domain_lookup] NOT[inputlookup cim_corporate_web_domain_lookup] | eval domain="*"+domain+"*"
description = This macro removes valid domains from the output
+1104 -764
View File
File diff suppressed because it is too large Load Diff
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-04-11T20:14:03 UTC
# On Date: 2023-04-18T21:44:55 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-04-11T20:14:03 UTC
# On Date: 2023-04-18T21:44:55 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
File diff suppressed because one or more lines are too long